Hello,
I'd suggest to rebuild all required packages (libraries) with
CFLAGS -Wa,--noexecstack so that assembled modules get tagged
as not needing executable stacks.1
The new binaries break PaX2 and thus weaken kernel security if one is using PaX to protect from overflows.
Patched binaries for 10.1 have been released at:
http://www.cerebrallab.com/files.php...ectfolder&id=3
But binaries for newer slackware versions are not available.
I would like to send a formal request to Patrick to compile all future binaries with --noexecstack, but I felt it would be better to recieve input from the slackware community before doing such.
The problem seems to first arise from Debian and has already been fixed in their CVS.
I know it's a bother to recompile it, but it will, IMHO, improve security.
References:
1
http://forums.grsecurity.net/viewtop...r=asc&start=15
2
http://pax.grsecurity.net/
Thank you,
Gian G. Spicuzza